Detecting port scans in a container orchestration system cluster
Abstract
Some embodiments of the invention provide a method for detecting port scans in a container orchestration system cluster that includes at least a first machine executing on a host computer. The method identifies a packet stream between the first machine and a second machine operating outside of the host computer. The method determines that the packet stream is potentially part of a port scanning operation based on an assessment that the packet stream includes less than a threshold number of packets during a particular time period. Based on said determination, the method identifies an amount of payload data exchanged between the first and second machines in the packet stream during the particular time period. When the identified amount of payload data is less than or equal to a threshold amount of payload data, the method classifies the stream as a probable port-scanning stream.
Claims
exact text as granted — not AI-modified1 . A method for detecting port scans in a container orchestration system cluster in a container network comprising at least a first machine executing on a host computer, the method comprising:
on the host computer:
identifying a packet stream between the first machine and a second machine operating outside of the host computer;
determining that the packet stream is potentially part of a port scanning operation based on an assessment that the packet stream comprises less than a threshold number of packets during a particular time period;
based on said determination, identifying an amount of payload data contained in the packet stream during the particular time period; and
when the identified amount of payload data is less than or equal to a threshold amount of payload data, classifying the stream as a probable port-scanning stream.
2 . The method of claim 1 further comprising generating a set of data associated with packets of the packet stream received at the host computer, wherein said determining comprises using the generated data to determine that the packet stream is potentially part of a port scanning operation.
3 . The method of claim 2 , wherein the generated set of data comprises packet statistics regarding the packet stream.
4 . The method of claim 3 , wherein the packet statistics comprises at least one of packet count and size of payload of the packets of the packet stream.
5 . The method of claim 4 , wherein generating the set of data comprises:
creating, for the packet stream, a record to store the packet stream statistics; and iteratively updating the record as new packets of the packet stream are received in order to update the statistics stored in the record.
6 . The method of claim 1 , wherein:
the first machine comprises a first pod executing on a node that executes on the host computer; and said identifying, determining, identifying and classifying operations are performed by a port scanning sensor that is implemented in an interface of the node.
7 . The method of claim 6 , wherein the node comprises a virtual machine (VM) and the interface comprises a VNIC (virtual network interface card).
8 . The method of claim 2 , wherein the set of data for the packet stream comprises at least a first IP (Internet Protocol) address and a first port number associated with the first machine, a second IP address and a second port number associated with the second machine, and the amount of payload data exchanged between the first and second machines.
9 . The method of claim 1 , wherein classifying the stream as a probable port-scanning stream further comprises determining whether the stream is a probable internal port-scanning stream or a probable external port-scanning stream, wherein:
when an IP address of the second machine (i) has made more than a specified threshold number of connections to private IP addresses that are within a range of IP addresses allocated for the container orchestration system cluster or (ii) is within the range of IP addresses allocated for the container orchestration system cluster, the packet stream is classified as a probable internal port-scanning stream; and when the IP address of the second machine (i) has made less than a specified threshold number of connections to private IP addresses that are within a range of IP addresses allocated for the container orchestration system cluster and (ii) is not within the range of IP addresses allocated for the container orchestration system cluster, the packet stream is classified as a probable external port-scanning stream.
10 . The method of claim 1 , wherein:
the threshold number of packets comprises a threshold number of packets exchanged in each direction; and the assessment that the packet stream comprises less than the threshold number of packets during the particular time period further comprises an assessment that the packet stream comprises less than the threshold number of packets exchanged in each direction during the particular time period.
11 . The method of claim 1 , wherein determining that the packet stream is part of a port scanning operation further comprises determining that the packet stream is an invalid packet stream based on the assessment.
12 . The method of claim 1 , wherein the threshold amount of payload data comprises a threshold amount of bytes exchanged between the first and second machines in the packet stream in each direction during the particular time period.
13 . The method of claim 12 , wherein the threshold amount of bytes comprises zero bytes.
14 . The method of claim 1 , wherein classifying the stream comprises classifying the stream as a probable port-scanning stream when the amount of payload data sent by the first machine is more than the threshold amount and the amount of payload data sent by the second machine is less than or equal to the threshold amount.
15 . The method of claim 1 , wherein when the identified amount of payload data exchanged between the first and second machines in the packet stream is greater than the threshold amount of payload data, the stream is not classified as a probable port-scanning stream.
16 . The method of claim 1 further comprising sending a notification regarding the classification of the packet stream to a set of one or more reporting servers, wherein the set of reporting servers send an alert identifying the probable port-scanning stream to an administrator of the container network based on the generated report.
17 . A non-transitory machine readable medium storing a program for execution by a set of processing units of a host computer, the program for detecting port scans in a container orchestration system cluster comprising at least a first machine executing on the host computer, the program comprising sets of instructions for:
identifying a packet stream between the first machine and a second machine operating outside of the host computer; determining that the packet stream is potentially part of a port scanning operation based on an assessment that the packet stream comprises less than a threshold number of packets during a particular time period; based on said determination, identifying an amount of payload data contained in the packet stream during the particular time period; and when the identified amount of payload data is less than or equal to a threshold amount of payload data, classifying the stream as a probable port-scanning stream.
18 . The non-transitory machine readable medium of claim 17 , the program further comprising a set of instructions for generating a set of data associated with packets of the packet stream received at the host computer, wherein the set of instructions for said determining comprises a set of instructions for using the generated data to determine that the packet stream is potentially part of a port scanning operation.
19 . The non-transitory machine readable medium of claim 18 , wherein:
the generated set of data comprises packet statistics regarding the packet stream; and the packet statistics comprises at least one of packet count and size of payload of the packets of the packet stream.
20 . The non-transitory machine readable medium of claim 19 , wherein the set of instructions for generating the set of data comprises sets of instructions for:
creating, for the packet stream, a record to store the packet stream statistics; and iteratively updating the record as new packets of the packet stream are received in order to update the statistics stored in the record.Join the waitlist — get patent alerts
Track US2024291830A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.